Alle Tags
Katalog-Tag

#supply-chain-security

Alle Repositories im öffentlichen Register, die dieses Tag tragen — aus ihren GitHub-Topics oder den von ihren Paket-Registries veröffentlichten Schlagwörtern. Die Gesundheit wird nach derselben versionierten Methodik gemessen wie im übrigen Register.

51 Einträge
Getaggt als „supply-chain-security“Geordnet nach Gesundheitsindex
Go
98AußergewöhnlichGesundheitsindex
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016. Juli 2026
Apache-2.016. Juli 2026 · Metriken 2.10.0
npm
96AußergewöhnlichGesundheitsindex
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/Monat4. Aug. 2026
MIT4. Aug. 2026 · Metriken 2.10.0
PyPI · npm
94AußergewöhnlichGesundheitsindex
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5.301/Monat16. Juli 2026
Apache-2.016. Juli 2026 · Metriken 2.10.0
PyPI · npm
94AußergewöhnlichGesundheitsindex
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2.808/Monat2. Aug. 2026
MIT2. Aug. 2026 · Metriken 2.10.0
PyPI · crates.io · npm
93AußergewöhnlichGesundheitsindex
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/Monat5. Sept. 2026
Apache-2.05. Sept. 2026 · Metriken 2.10.0
Go · npm
92ExzellentGesundheitsindex
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417. Juli 2026
Apache-2.017. Juli 2026 · Metriken 2.10.0
Go
90ExzellentGesundheitsindex
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421. Juli 2026
Apache-2.021. Juli 2026 · Metriken 2.10.0
npm
90ExzellentGesundheitsindex
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1.759↓ 35.4K/Monat17. Juli 2026
Apache-2.017. Juli 2026 · Metriken 2.10.0
crates.io
90ExzellentGesundheitsindex
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3.01616. Juli 2026
Apache-2.016. Juli 2026 · Metriken 2.10.0
crates.io
89ExzellentGesundheitsindex
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3.03617. Juli 2026
Apache-2.017. Juli 2026 · Metriken 2.10.0
crates.io
89ExzellentGesundheitsindex
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3.04719. Juli 2026
Apache-2.019. Juli 2026 · Metriken 2.10.0
Go · npm
89ExzellentGesundheitsindex
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 2829. Juli 2026
Apache-2.029. Juli 2026 · Metriken 2.10.0
Go · PyPI
87ExzellentGesundheitsindex
IronSecCo/ironclaw
Security-first, self-hosted AI agents - isolation you can prove, not just promise.
Go★ 1929. Aug. 2026
AGPL-3.029. Aug. 2026 · Metriken 2.10.0
Go
86ExzellentGesundheitsindex
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024. Juli 2026
Apache-2.024. Juli 2026 · Metriken 2.10.0
Go · PyPI
86ExzellentGesundheitsindex
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917. Juli 2026
Apache-2.017. Juli 2026 · Metriken 2.10.0
Go · PyPI
86ExzellentGesundheitsindex
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 316. Juli 2026
MIT16. Juli 2026 · Metriken 2.10.0
Go
86ExzellentGesundheitsindex
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 4219. Juli 2026
Apache-2.019. Juli 2026 · Metriken 2.10.0
npm · PyPI
84ExzellentGesundheitsindex
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7.189/Monat22. Aug. 2026
AGPL-3.022. Aug. 2026 · Metriken 2.10.0
PyPI · npm
84ExzellentGesundheitsindex
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1.281↓ 10.9K/Monat24. Aug. 2026
MIT24. Aug. 2026 · Metriken 2.10.0
PyPI
84ExzellentGesundheitsindex
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022. Aug. 2026
Eigene Lizenz22. Aug. 2026 · Metriken 2.10.0
Go · npm
83ExzellentGesundheitsindex
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 415. Aug. 2026
AGPL-3.015. Aug. 2026 · Metriken 2.10.0
Go
83ExzellentGesundheitsindex
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 11. Aug. 2026
Apache-2.01. Aug. 2026 · Metriken 2.10.0
Go
81ExzellentGesundheitsindex
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823. Juli 2026
Apache-2.023. Juli 2026 · Metriken 2.10.0
npm · PyPI
80ExzellentGesundheitsindex
delimit-ai/delimit-mcp-server
The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3.625/Monat3. Aug. 2026
MIT3. Aug. 2026 · Metriken 2.10.0
PyPI
78GutGesundheitsindex
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1.928/Monat17. Juli 2026
Apache-2.017. Juli 2026 · Metriken 2.10.0
Go
78GutGesundheitsindex
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420. Juli 2026
Apache-2.020. Juli 2026 · Metriken 2.10.0
Go
77GutGesundheitsindex
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019. Juli 2026
Apache-2.019. Juli 2026 · Metriken 2.10.0
Go
77GutGesundheitsindex
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 1575. Sept. 2026
Eigene Lizenz5. Sept. 2026 · Metriken 2.10.0
Go
75GutGesundheitsindex
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221. Juli 2026
BSD-3-Clause21. Juli 2026 · Metriken 2.10.0
PyPI · npm
75GutGesundheitsindex
gautamvarmadatla/mcpsafetywarden
MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2.923/Monat1. Aug. 2026
Eigene Lizenz1. Aug. 2026 · Metriken 2.10.0